Junglewise Threat Intelligence

CVE-2026-11650: Google Chrome use after free in V8

CVE-2026-11650 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's V8 engine, which is responsible for processing JavaScript on websites. An attacker could exploit this flaw by tricking a user into visiting a specially crafted webpage, potentially allowing the attacker to execute unauthorized code on the user's computer. While the exploit is restricted to the browser's security sandbox, it represents a significant risk to data privacy and system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of complex JavaScript or HTML structures. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page; when a victim visits the site, the attacker can achieve arbitrary code execution within the context of the browser's sandbox. This vulnerability was addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-08: disclosed: Reported by Google internal researchers
  • 2026-06-08: patched: Fixed in stable channel update 149.0.7827.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats